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IN THECT.ATMS: 

A status of all the claims of the present Application is presented below: 

1. (Original) A method of displaying data related to an intrusion event on a 
computer system, comprising: 

capturing data related to the intrusion event; 

decoding the captured data from a first predetermined format to a second 
predetermined format decipherable by humans, the decoded data comprising data components 
of intrusion signature, data summary, and detailed data; 

correlating data components of the intmsion signature, data summary and detailed 
data to one another; 

retrieving an web browser-based template; and 

graphically displaying the correlated decoded data components using the web 
browser-based template. 

2. (Original) The method, as set forth in claim 1, wherein graphically displaying the 
correlated decoded data components comprises graphically highlighting correlated data 
components of intrusion signature, data summary and detailed data using the web browser- 
based template. 

3. (Original) The method, as set forth in claim 1, wherein graphically displaying the 
correlated decoded data components comprises: 

receiving a user input selecting a displayed data component; and 
graphically highlighting data components correlated to the selected data component 
using the web browser-based template. 

4. (Original) The method, as set forth in claim 1, wherein graphically displaying the 
correlated decoded data comprises: 

receiving a user input selecting a displayed data component; 

graphically highlighting the user selected data component using the web browser- 
based template; and 
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graphically highlighting data components correlated to the selected data component 
using the web browser-based template. 

5. (Original) The method, as set forth in claim 1, wherein capturing data comprises 
capturing network data packets of the intrusion event. 

6. (Original) The method, as set forth in claim 1, wherein decoding the captured 
data comprises decoding the captured data from a binary format to a human-readable text 
format. 

7. (Original) The method, as set forth in claim 1, wherein decoding the captured 
data comprises decoding the captured data to decoded data having a data link layer protocol 
header, a network layer protocol header, a network layer protocol data summary, and packet 
data in hexadecimal format. 

8. (Original) The method, as set forth in claim 1, wherein decoding the captured 
data comprises decoding the captured data to decoded data having an Ethemet header, an IP 
header, an IP data simimary, and packet data in hexadecimal format. 

9. (Original) A method of displaying data of an intrusion detection system, 
comprising: 

capturing, from a network, data related to an intrusion event in response to detecting 
an intrusion signature in the network data; 

decoding the captured data from a predetermined format to a human-readable format, 
the decoded data comprising data components of network header data, data summary, and 
detailed data; 

determining a correlation relationship between the data components of the intrusion 
signature, network header data, data summary and detailed data to one another; and 

displaying the correlated decoded data components by using a web browser-based 
template. 
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10. (Original) The method, as set forth in claim 9, wherein graphically displaying 
the correlated decoded data comprises: receiving a user input selecting a displayed data 
component; and graphically highlighting all data components correlated to the selected data 
component using an HTML template. 

1 1 . (Original) The method, as set forth in claim 9, wherein graphically displaying 
the correlated decoded data comprises: receiving a user input selecting a displayed data 
component; graphically highlighting the user selected data component; and graphically 
highlighting data components correlated to the selected data component. 

12. (Original) The method, as set forth in claim 9, wherein capturing data comprises 
capturing network data packets of the intrusion event in response to detecting the presence of 
a predetermined data pattem in the network data packet. 

13. (Original) The method, as set forth in claim 9, wherein decoding the captured 
data comprises decoding the captured data from a binary format to a text format. 

14. (Original) The method, as set forth in claim 9, wherein decoding the captured 
data comprises decoding the captured data to decoded data having a data link layer protocol 
header, a network layer protocol header, a network layer protocol data summary, and packet 
data in hexadecimal format. 

15. (Original) The method, as set forth in claim 9, wherein decoding the captured 
data comprises decoding the captured data to decoded data having an Ethemet header, an IP 
header, an IP data summary, and packet data in hexadecimal format. 
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16. (Original) A system of presenting data of an intrusion detection system, 
comprising: 

a network driver capturing data related to an intrusion event upon detecting a 
predetermined intrusion signature; 

a decode engine decoding the captured data from a predetermined format to a 
predetermined format decipherable by humans, the decoded data comprising data components 
of intrusion event data, data summary, and detailed data; and 

a user interface graphically correlating data components of the intrusion signature, 
intrusion event data, data summary and detailed data to one another and displaying the 
correlated decoded data components according to a web browser-based format. 

17. (Original) The system, as set forth in claim 16, wherein the user interface 
graphically highlights correlated data components of intrusion event data, data summary and 
detailed data using an HTML template. 

18. (Original) The system, as set forth in claim 16, wherein the user interface is 
operable to receive a user input selecting a displayed data component, and graphically 
highlights all data components correlated to the selected data component using a web-based 
display template. 

19. (Original) The system, as set forth in claim 16, further comprising a web server 
operable to transmit a file in a web-browser displayable format having the correlated and 
decoded data components. 

20. (Original) The system, as set forth in claim 16, wherein the network driver 
captures network data packets of the intrusion event in response to the intrusion detection 
system detecting a predetermined data pattern corresponding to the predetermined intrusion 
signature. 

21. (Original) The system, as set forth in claim 16, wherein the decode engine 
decodes the captured data from a binary format to a human-readable text format. 



Pages 



Application Serial No. 10/002,064 



PATENT 



22. (Original) The system, as set forth in claim 16, wherein the decode engine 
decodes the captured data to decoded data components having a data link layer protocol 
header, a network layer protocol header, a network layer protocol data summary, and packet 
data in hexadecimal format. 

23. (Original) The system, as set forth in claim 16, wherein the decode engine 
decodes the captured data to decoded data components having an Ethemet header, an DP 
header, an DP data summary, and packet data in hexadecimal format. 
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